An HTTP 404 during a Configuration Manager (SCCM) client installation means a web server or intermediary could not find the requested URL. The fastest way to fix it is to identify the exact URL in ccmsetup.log, then determine which server or network layer returned the response. The error alone does not prove that the management point is broken, and reinstalling the client will not fix a bad URL or missing server-side content.
Find the failing URL in the client setup log
On the affected computer, start with C:WindowsccmsetupLogsccmsetup.log. Configuration Manager records the client installation process there. Open it in CMTrace or inspect the latest entries in PowerShell:
Get-Content 'C:WindowsccmsetupLogsccmsetup.log' -Tail 150
Search for the first HTTP failure, not just the final setup exit line:
Select-String `
-Path 'C:WindowsccmsetupLogsccmsetup.log' `
-Pattern '404|0x80190194|0x87d0027e|CCMHTTP|ccmsetup.cab|CCM_Client|CCM_Proxy|site version' `
-Context 3,5
Record the complete URL, including hostname, protocol, port, and path, and note what it was requesting: bootstrap files such as ccmsetup.cab, site-version information, or later client content. Common paths include /CCM_Client/ccmsetup.cab and CMG routes containing CCM_Proxy_MutualAuth or CCM_Proxy_ServerAuth, but the path in your log—not an assumed standard URL—is the one to test.
Recommended Free Tools
#1 Best Overall
- 3.5 Inch Hot Plug Hard Drive PowerEdge T340 Tower Server Chassis
- Microsoft Windows Server 2019 Standard Operating System
- Processors: Intel Xeon E-2124 Quad-Core 3.3GHz 8MB CPU, Up To 4.3GHz Turbo
- Memory: 32GB (2 x 16GB) DDR4 PC4-21300 2666MHz Unbuffered Memory
- Hard Drive: 8TB (4 x 2TB) 7.2K RPM 6Gb/s SATA 3.5 Inch HDDs in RAID
What the error codes do and do not tell you
- HTTP 404: The responding web server or intermediary says the requested resource or route was not found.
0x80190194: A WinHTTP-style code often associated with HTTP 404.0x87d0027eorCCM_E_BAD_HTTP_STATUS_CODE: Configuration Manager wrapper errors that can accompany an HTTP/content-location failure; they are not universal one-to-one mappings across every installation stage or build.- MSI error
1603: A Windows Installer failure, not the HTTP status itself. If setup has reached the MSI stage, inspectclient.msi.logbefore treating the issue as a download problem.
A community example shows the logged pairing of HTTP 404 and 0x80190194 during a client-file download: SCCM client-installation error example. Treat it as an illustration of the log pattern, not as a universal error-code specification.
Run a quick network and URL check
Use the hostname and exact URL from the log. Replace the example values below; do not guess the path.
- Check DNS:
Resolve-DnsName mp01.contoso.com - Check the relevant listener:
Test-NetConnection mp01.contoso.com -Port 80 Test-NetConnection mp01.contoso.com -Port 443Test the port actually used in the URL. Configuration Manager communication depends on the site-system configuration and HTTP/HTTPS settings; see Microsoft’s client firewall and port reference.
- Request the exact logged URL:
$uri = 'https://mp01.contoso.com/CCM_Client/ccmsetup.cab' try { Invoke-WebRequest -Uri $uri -UseBasicParsing -MaximumRedirection 0 } catch { $_.Exception.Response.StatusCode.value__ $_.Exception.Response.StatusDescription }Use this sample URL only if it matches the one in your log. For a file-download endpoint, you can also inspect response headers with
curl.exe -I 'https://mp01.contoso.com/CCM_Client/ccmsetup.cab'.What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Rank #2
Dell PowerEdge T40 Server, BTX Intel Xeon E-2224G 3.5GHz, 8GB 2666MT/s DDR4, 1TB 7.2K RPM SATA, Windows Server License is not Included- Windows server license is not included
| Result | What it suggests | Next check |
|---|---|---|
| DNS lookup fails | Name resolution, suffix, record, or hostname problem | Correct the name or record before testing the endpoint again. |
| TCP connection fails | Firewall, route, proxy, or listener problem | Restore network reachability to the configured port. |
| HTTPS certificate error | Trust, name, chain, revocation, or IIS binding issue | Resolve TLS validation before interpreting the application response. |
| HTTP 404 | The responding server or intermediary does not recognize that path | Check the route, role, content, proxy, and load-balancer path. |
| 401 or 403 | The route may exist, but authentication or authorization blocks access | Check the expected authentication and client context. |
| 405 | The route exists but does not accept the request method | Confirm the endpoint and method expected by the client. |
| 500, 502, or 503 | Server role, proxy, or backend may be unhealthy | Inspect the responding layer and its backend health. |
| 200 | The URL responds from this test context | Check whether setup runs under a different identity or network path. |
A browser or interactive PowerShell test is not conclusive: it may use a different proxy, credentials, authentication negotiation, or user context than the Local System account running ccmsetup. A 404 can also originate from IIS on the management point, a reverse proxy, load balancer, web application firewall, corporate proxy, CMG, or cloud-storage endpoint. Compare response headers and server-side logs to identify the responding layer.
Match the failure to the installation method
Configuration Manager supports multiple client deployment methods, and they do not share all prerequisites or failure points. Microsoft’s Windows client deployment guidance describes these methods and their setup requirements.
| Installation method | Where to focus |
|---|---|
Manual install from \<site-server>SMS_<site-code>Client |
Confirm the share is the intended, current client source and that the selected server and files are reachable. |
Manual install with /MP: |
Verify the management-point name, protocol, and resulting URL in ccmsetup.log. |
| Client push | Separate failure to contact or start setup on the target from a later HTTP download failure; inspect CCM.log as well as the client setup log. |
| Group Policy or software update-based installation | Confirm the deployed command or package uses the correct source and that the target can reach the resulting endpoint. |
| Task sequence or OS deployment | Inspect smsts.log and test from the task-sequence execution environment, including WinPE if applicable. |
| Intune/MDM, internet-based management, or CMG | Follow the cloud endpoint, authentication, certificate, and content-location flow rather than assuming an on-premises MP path. |
| Workgroup client | Check manual configuration, DNS, authentication, and assignment prerequisites; workgroup clients cannot use client push or locate MPs through Active Directory Domain Services. |
Fix an incorrect or unavailable management-point path
If the URL points to an on-premises management point, check the URL’s hostname, port, protocol, and path against the intended role. Microsoft documents that client installation files are available from the site server’s Client folder and shared to the network; CCMSetup.exe can also obtain files from a management point. See Deploy clients to Windows computers.
- Validate the supplied management point. Check whether the command line’s
/MP:value names the intended, working MP. A wrong alias, protocol, port, or server can lead setup to a valid web server that does not host the requested Configuration Manager route. - Check role and IIS health. Confirm the MP role is installed and healthy, and that the IIS site, bindings, and expected hostname and port align with the client’s HTTP/HTTPS configuration. Review IIS logs for the request time, URI, status, and substatus.
- Bypass aliases when possible. If a load balancer or reverse proxy is in the path, compare the alias with each backend MP directly. A direct MP returning the expected response while the alias returns 404 points toward routing or path rewriting. If only one backend fails, investigate inconsistent role, IIS, or content state.
- Check site and client content freshness. After a site upgrade or role change, compare the site server’s client source with what the MP or other content location serves. A stale source, incomplete package, or replication lag can make the result vary by server.
For a documented manual install pattern, Microsoft uses CCMSetup.exe /mp:SMSMP01 /logon SMSSITECODE=AUTO FSP=SMSFP01. The /mp: switch is a CCMSetup option; SMSSITECODE is a Client.msi property and follows the CCMSetup parameters. Adapt the server names and site code to your environment.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- MODEL P74439-005: Compact and affordable HPE ProLiant MicroServer Gen11 powered by Intel Pentium Gold G7400 3.7GHz processor, ideal for file sharing, NAS, and basic business workloads
- READY OUT OF THE BOX: Includes 16GB DDR5 UDIMM memory (expandable to 128GB), one 1TB SATA 6G Business Critical HDD, embedded Intel VROC SATA, dedicated iLO-M.2 port kit, 180w external power adapter and 1/1/1 warranty for dependable plug-and-play server operation
- WHISPER-QUIET & SPACE-SAVING: Ultra-compact mini tower design fits easily in small office spaces; supports wall, flat, or vertical placement for deployment flexibility
- INTEGRATED REMOTE MANAGEMENT: Comes with HPE iLO 6 and embedded TPM 2.0 for secure, license-free remote server administration through shared port access
- EXPANDABLE DESIGN: Two PCIe slots (including PCIe 5.0) and four LFF-NHP drive bays provide robust options for storage and component scalability. Features new MR408i-p controller support for enhanced storage performance
For an on-premises source, a client can be started from a site share such as \MPSERVERSMS_ABCClientCCMSetup.exe, or with a command such as CCMSetup.exe /mp:mp01.contoso.com SMSSITECODE=ABC. Use current, appropriate installation files. Do not run Client.msi directly: Microsoft’s documented flow uses CCMSetup.exe to copy prerequisites and invoke the MSI.
Diagnose a 404 for bootstrap or client content
First establish who supplied the URL in the log. A request for ccmsetup.cab is an early bootstrap/content path; a site-version request points to discovery or MP access; a later cloud-storage or distribution-point URL has a different source. The literal path is not universal, so test only the URL that setup actually recorded.
- If the URL is served by an MP, check the MP role, IIS request logs, and client-content exposure.
- If it is a CMG or cloud URL, validate the CMG and its configured content path; whether the CMG serves or retrieves the client content depends on the deployment design.
- If the URL comes from a distribution point or stale local
/Source:directory, confirm the referenced location has the needed client version and files. - If the same URL succeeds on one client but not another, compare DNS results, proxy path, authentication context, and backend selection.
Microsoft has documented a historical client-setup failure involving downloads from a cloud distribution point and a bad HTTP status. That case supports checking the specific content URL and source rather than assuming a local MSI fault: client setup unable to download cloud distribution-point content.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Follow a separate branch for CMG and internet-based installs
A CMG install can involve several requests: CMG or Microsoft Entra information, authentication and token acquisition, site information, a client content location, and then the client files. A failure at one transition may end with a generic setup failure, so identify the precise URL and stage first. Microsoft’s Microsoft Entra authentication workflow for CCMSetup describes this flow and its certificate and content considerations.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #4
- This Certified Refurbished product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high-performance bar may offer Certified Refurbished products on Amazon.com.
- Dell Optiplex 3050 SFF Desktop computer PC, Intel Quad Core i5-6500 up to 3.6GHz, 16GB DDR4, 256GB SSD
- Includes: USB Keyboard & Mouse, USB WiFi adapter, Microsoft office 30 days free trail.
- Port: Front: USB 3.0(2), USB 2.0(2); Rear: DP, HDMI, USB 3.0(2), USB 2.0(2), RJ-45.
- Support 4K (3840x2160) Dual display, makes it easy to connect two monitors at the same time, and you can expand working Windows, mirror content, or expand a single window across multiple monitors.
- Verify the CMG hostname used by setup and compare it with the hostname in the failing URL.
- Check CMG connection-point and tenant onboarding status, Microsoft Entra configuration, and whether the device’s join state and authentication path meet your design.
- Validate the relevant root CA trust, CMG server-authentication certificate chain, and certificate-name match. If revocation checking is enabled, confirm CRL availability; do not disable it as a generic workaround.
- Confirm the CMG/content configuration can provide the client version being requested, or that the configured alternate content source is reachable.
- Compare a failing CMG request with an intended direct-MP path where the device’s network and security design permits it. A difference isolates the cloud path without proving which CMG component is at fault.
For internet-based installation from local media, Microsoft documents a pattern such as CCMSetup.exe /source:D:Clients /UsePKICert CCMHOSTNAME=server1.contoso.com SMSSIGNCERT=siteserver.cer SMSSITECODE=ABC. Options such as /NoCRLCheck, FSP=, or CCMALWAYSINF=1 depend on the environment and security design; they are not general 404 fixes.
Check client-push and task-sequence context
Client push
Client push has a separate initial connection phase: the site server must reach the target and use an account with local administrator rights. If setup never starts on the client, inspect site-server CCM.log, firewall, SMB, administrative shares, RPC, and credentials before investigating an HTTP URL. Microsoft says client push retries hourly for up to seven days when the site server cannot contact or start setup on a client; see its client deployment guidance. If setup did start and its log shows 404, follow that URL to its actual source.
Task sequences and OS deployment
Use smsts.log to identify the task-sequence step and environment in which setup failed. A URL that works in the full operating system may fail in WinPE because the network configuration, name resolution, proxy path, credentials, or selected MP/DP differs. Test from the same execution context and check whether the task sequence references current client media or a valid content location.
If setup reached the MSI stage, switch logs
When Client.msi has started, use C:WindowsccmsetupLogsclient.msi.log to investigate the local installation. Focus on the recorded MSI return code and evidence about prerequisites, permissions, pending reboot, security software, WMI registration, or DLL loading. A documented PolicyAgentProvider.dll/WMI failure with MSI error 1603 is a separate local-installation issue, not proof that an earlier 404 caused the failure: Microsoft’s PolicyAgentProvider.dll troubleshooting article.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →After installation, use LocationServices.log, ClientLocation.log, ClientIDManagerStartup.log, and CcmMessaging.log to diagnose assignment, registration, location, or communication problems. A successful bootstrap download alone does not establish that the client is assigned, registered, or receiving policy. Application deployment errors such as 0x87D00202 belong to a different troubleshooting path; see Microsoft’s application installation error-code reference.
Use this decision sequence to identify the failing layer
- Find the first failing request in
ccmsetup.logand copy its full URL and timestamp. - Resolve its hostname and test the URL’s port from the affected device and installation context.
- Request the exact URL and record the response code and headers.
- Check the server, IIS, proxy, CMG, or cloud logs that correspond to that timestamp and path.
- Compare the same request through a direct MP hostname, an alias, or another backend where appropriate.
- Only after the endpoint returns the expected content, rerun the correct
CCMSetup.execommand or deployment method.
For further log triage, Microsoft identifies ccmsetup.log as the client installation record and CCM.log as the site-server log for client-push connection issues in its client deployment documentation.
Quick Recap
Prevent the same 404 from recurring
- Keep MP, CMG, and content-source configuration aligned when upgrading or changing roles.
- Test each load-balancer backend and verify that aliases preserve the expected host, protocol, and path.
- Retire stale DNS aliases and update commands, packages, task sequences, and scripts that still reference them.
- Validate client installation from representative networks and execution contexts after site or certificate changes.
- Maintain known-good client source media and confirm that deployments use
CCMSetup.exewith the intended source and site settings.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

